Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of in the bound dynamic text was never escaped under any circumstances. The unescaped closing tag was serialized directly into the output HTML (e.g. ). When parsed by a browser, it closes the
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50556.json"
}{
"cpe": [
"cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next0:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next1:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next10:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next11:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next12:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next2:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next3:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next4:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next5:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next6:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next7:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next8:*:*:*:node.js:*:*",
"cpe:2.3:a:angular:angular:22.0.0:next9:*:*:*:node.js:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "18.2.14"
},
{
"introduced": "19.0.0"
},
{
"fixed": "19.2.25"
},
{
"introduced": "20.0.0"
},
{
"fixed": "20.3.24"
},
{
"introduced": "21.0.0"
},
{
"fixed": "21.2.16"
},
{
"introduced": "22.0.0-next0"
},
{
"last_affected": "22.0.0-next0"
},
{
"introduced": "22.0.0-next1"
},
{
"last_affected": "22.0.0-next1"
},
{
"introduced": "22.0.0-next10"
},
{
"last_affected": "22.0.0-next10"
},
{
"introduced": "22.0.0-next11"
},
{
"last_affected": "22.0.0-next11"
},
{
"introduced": "22.0.0-next12"
},
{
"last_affected": "22.0.0-next12"
},
{
"introduced": "22.0.0-next2"
},
{
"last_affected": "22.0.0-next2"
},
{
"introduced": "22.0.0-next3"
},
{
"last_affected": "22.0.0-next3"
},
{
"introduced": "22.0.0-next4"
},
{
"last_affected": "22.0.0-next4"
},
{
"introduced": "22.0.0-next5"
},
{
"last_affected": "22.0.0-next5"
},
{
"introduced": "22.0.0-next6"
},
{
"last_affected": "22.0.0-next6"
},
{
"introduced": "22.0.0-next7"
},
{
"last_affected": "22.0.0-next7"
},
{
"introduced": "22.0.0-next8"
},
{
"last_affected": "22.0.0-next8"
},
{
"introduced": "22.0.0-next9"
},
{
"last_affected": "22.0.0-next9"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}